CVE-2011-0718
published 2011-02-25CVE-2011-0718: Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute…
PriorityP426medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.26%
66.3th percentile
Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | network_satellite_server | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jh92-c236-hm8p: Red Hat Network (RHN) Satellite Server 5
ghsa_unreviewed·2022-05-17
CVE-2011-0718 [MEDIUM] CWE-287 GHSA-jh92-c236-hm8p: Red Hat Network (RHN) Satellite Server 5
Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.
Red Hat
Spacewalk: Prone to brute force password guessing attacks
vendor_redhat·2011-02-23·CVSS 5.8
CVE-2011-0718 [MEDIUM] Spacewalk: Prone to brute force password guessing attacks
Spacewalk: Prone to brute force password guessing attacks
Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to conduct brute force password guessing attacks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0717 CVE-2011-0718 spacewalk-backend various flaws [fedora-all]
bugzilla·2011-02-23·CVSS 5.8
CVE-2011-0717 [MEDIUM] CVE-2011-0717 CVE-2011-0718 spacewalk-backend various flaws [fedora-all]
CVE-2011-0717 CVE-2011-0718 spacewalk-backend various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=672159
Please note: this issue affects multiple s
Bugzilla
CVE-2011-0718 Satellite, Spacewalk: Prone to brute force password guessing attacks
bugzilla·2011-01-24·CVSS 5.8
CVE-2011-0718 [MEDIUM] CVE-2011-0718 Satellite, Spacewalk: Prone to brute force password guessing attacks
CVE-2011-0718 Satellite, Spacewalk: Prone to brute force password guessing attacks
A flaw was found in the way Red Hat Network (RHN) Satellite
and Spacewalk services managed user authentication. A time
delay was not inserted after each failed log in, which could
allow a remote attacker to conduct a password guessing attack
efficiently.
Acknowledgements:
Red Hat would like to thank Thomas Biege of the SuSE Security Team
for reporting this issue.
Discussion:
The CVE identifier of CVE-2011-0718 has been assigned to this issue.
---
This issue has been addressed in following products:
Red Hat Network Satellite Server v 5.4
Via RHSA-2011:0300 https://rhn.redhat.com/errata/RHSA-2011-0300.html
---
Created spacewalk-backend tracking bugs for this issue
Affects: fedora-all [bug 679887]
http://secunia.com/advisories/43487http://www.redhat.com/support/errata/RHSA-2011-0300.htmlhttp://www.securityfocus.com/bid/46528http://www.securitytracker.com/id?1025116http://www.vupen.com/english/advisories/2011/0491https://bugzilla.redhat.com/show_bug.cgi?id=672159https://exchange.xforce.ibmcloud.com/vulnerabilities/65657http://secunia.com/advisories/43487http://www.redhat.com/support/errata/RHSA-2011-0300.htmlhttp://www.securityfocus.com/bid/46528http://www.securitytracker.com/id?1025116http://www.vupen.com/english/advisories/2011/0491https://bugzilla.redhat.com/show_bug.cgi?id=672159https://exchange.xforce.ibmcloud.com/vulnerabilities/65657
2011-02-25
Published